Article
Cyber Resilience Act: New Vulnerability Reporting Requirements Now In Force
The EU Cyber Resilience Act introduces mandatory reporting obligations for manufacturers of digital products, requiring them to notify authorities within 24 hours of discovering actively exploited vulnerabilities or severe security incidents. This regulation establishes strict timelines for early warnings, detailed vulnerability notifications, and final reports, fundamentally changing how manufacturers must respond to cybersecurity threats.
Browne Jacobson